CyberRota Analysis
AI-GeneratedVersions of n8n prior to 2.39.6 and between 2.40.0 and 2.40.1 are vulnerable to a credentials leak that exposes unencrypted usernames and passwords to unvalidated hosts. This flaw allows attackers with permission to update credentials to redirect sensitive information to arbitrary destinations, effectively bypassing security measures. Organizations using affected versions should prioritize updating to mitigate the risk of credential theft and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.